Command Injection Vulnerability in MongoDB Extension for Visual Studio Code
CVE-2026-84967
5.1MEDIUM
What is CVE-2026-84967?
The MongoDB extension for Visual Studio Code has a vulnerability that stems from improper handling of special characters in user-supplied connection strings. This flaw allows an unauthenticated remote attacker to craft malicious input which, if accepted by a developer, results in unauthorized command execution within the extension’s integrated terminal. The attacker does not need privileges on the developer's machine; however, they must convince the developer to interact with the malicious input. Importantly, the terminal confirmation does not visually disclose the tampered text to the developer, increasing the risk of exploitation.
Affected Version(s)
MongoDB for VS Code 1.13.0 < 1.17.1